IPSEC Phase 1 and Phase 2 is up but return traffic not observed on Fortigate
Hi,
Issue is as above. Peering firewall is a Cisco Firepower.
Site A - FW A (Fortigate) <IPSEC tunnel> FW B (Cisco Firepower) - Site B
IPSEC P1, P2 is up and green. We're attempting SSH to reach Site B machine from Site A. We are seeing the traffic leaving from site A, routed through the tunnel interface via a diagnose sniffer packet, and from the Site B machine tcpdump we are seeing the Syn traffic reaching the machine and return traffic sent. FW B's administrator is seeing the return traffic from Site B as well and forwards it back to Site A, but we're not seeing the traffic on Fortigate (FW A) and causing a timeout of the SSH attempt either from diagnose sniffer packet, network capture from the Fortigate or a diagnose debug flow.
I've been scratching my head and not too sure on what's the next step I could take, so any feedback or questions is appreciated.
Thanks in advance.
